CVE-2026-8501
Awaiting Analysis Awaiting Analysis - Queue
Improper Access Control in PCTCore64.sys Windows Kernel Driver

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: CERT/CC

Description
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-21
AI Q&A
2026-06-01
EPSS Evaluated
2026-06-20
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
pc_tools internet_security *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-782 The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-8501 is a vulnerability in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security. The driver improperly controls access to its device interface, allowing any user-mode process to interact with it and invoke privileged IOCTL commands without proper restrictions.

This flaw enables a local attacker who can access or load the vulnerable driver to perform sensitive and privileged operations on the system by exploiting the exposed interface.

Exploitation can include actions such as system-wide handle enumeration, cross-process handle manipulation, credential extraction from critical processes like lsass.exe, and forced termination of arbitrary processes, including those protected by Protected Process Light (PPL).

Although the PC Tools Internet Security product was discontinued in 2013, the driver remains signed and exploitable.

Impact Analysis

Successful exploitation of this vulnerability can lead to serious security impacts including credential theft, defense evasion, privilege escalation, and broader system compromise.

  • Credential theft by extracting sensitive information from protected processes.
  • Defense evasion by manipulating system handles and processes.
  • Privilege escalation allowing attackers to gain higher system privileges.
  • Forced termination of arbitrary processes, including those with protection mechanisms.
Compliance Impact

CVE-2026-8501 allows local attackers to perform sensitive privileged operations such as credential extraction from lsass.exe, privilege escalation, and broader system compromise by exploiting improper access control in a signed Windows kernel driver.

Such unauthorized access and potential credential theft can lead to violations of data protection and privacy requirements mandated by standards like GDPR and HIPAA, which require strict controls over access to sensitive personal and health information.

Organizations using affected systems without mitigation may face increased risk of non-compliance due to potential unauthorized disclosure or manipulation of protected data.

Mitigations such as removing the vulnerable driver, restricting administrative privileges, and enabling protections like Hypervisor-protected Code Integrity (HVCI) and Credential Guard are recommended to reduce this risk and help maintain compliance.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8501. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart